For the complete documentation index, see llms.txt. This page is also available as Markdown.

SCCM log files enumeration

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Analytics

Detector Tags

Microsoft SCCM Analytics

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Log Enumeration (T1654)

Severity

Informational

Description

Multiple local SCCM logs were accessed within a short period of time.

Attacker's Goals

Enumerate data about the SCCM configuration, infrastructure and deployments.

Investigative actions

  • Check suspicious network connections from the process or host.

  • Check if the user account that initiated the enumeration is supposed to access these files.

Variations

Suspicious SCCM log files enumeration

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Log Enumeration (T1654)

Severity

Low

Description

Multiple local SCCM logs were abnormally accessed within a short period of time.

Attacker's Goals

Enumerate data about the SCCM configuration, infrastructure and deployments.

Investigative actions

  • Check suspicious network connections from the process or host.

  • Check if the user account that initiated the enumeration is supposed to access these files.

Was this helpful?